971304e020f22fe832237a1cabb526146504326390a2facd0d31894d64bf6811

Z-Journal

Andreas Baumann

Publisher:
IMU - Andreas Baumann  (signed by Andreas Baumann)

Product:
Z-Journal

Description:
Z-Software Journal-View

Version:
3.07.0003

MD5:
a6f554de5882a7f1082085c5ac1fca69

SHA-1:
6c2279ee86f22bda643ff0b426c88824906ba6e7

SHA-256:
971304e020f22fe832237a1cabb526146504326390a2facd0d31894d64bf6811

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 4:19:00 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.VbCrypt.250
9.0.1.05190

File size:
200.5 KB (205,344 bytes)

Product version:
3.07.0003

Copyright:
© A.Baumann 2006 - 2013

Original file name:
z-journal.exe

Language:
German (Germany)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/10/2012 1:00:00 AM

Valid to:
2/19/2014 12:59:59 AM

Subject:
CN=Andreas Baumann, OU=SECURE APPLICATION DEVELOPMENT, O=Andreas Baumann, L=Berlin, S=Berlin, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
753BC7598F9981E43A04D477D6382D3D

File PE Metadata
Compilation timestamp:
9/5/2013 7:48:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:OOCWghWZ14/JBFyTiYiJ0nLrCU8b0/Zsd:5CdWYrFy2YWUqJYsd

Entry address:
0x4194

Entry point:
B8, C8, 02, 49, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 16, 2E, D6, E1, 23, 39, D2, B8, C9, C5, 53, FB, 1F, 90, 45, 61, 2F, 5A, 0B, F2, 9F, 3C, 5C, F4, 85, 8A, 4E, 6C, 5F, B5, DD, 00, 5A, BE, 22, 19, FD, 7D, 30, F6, 06, 02, B4, F7, 4D, BD, 39, 9D, 2D, A4, AE, D7, AE, 17, FA, EC, 83, FA, 37, C0, B7, 9E, 81, AF, C2, 54, 92, D7, 4D, F2, CD, 6E, 10, D8, 55, 74, BA, DF, AB, 18, 35, 74, FD, 71, 9F, 2C, 73, 0F, E8, 8B, DA, F0, 1E...
 
[+]

Entropy:
7.9020

Packer / compiler:
PECompact v2

Code size:
524 KB (536,576 bytes)

The file 971304e020f22fe832237a1cabb526146504326390a2facd0d31894d64bf6811 has been discovered within the following program.

Z-DBackup  by IMU Andreas Baumann
www.z-dbackup.de.de
About 6% of users remove it
 
Powered by Should I Remove It?